Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4033
Description:Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4033
BugTraq ID: 32204
http://www.securityfocus.com/bid/32204
Cert/CC Advisory: TA08-316A
http://www.us-cert.gov/cas/techalerts/TA08-316A.html
HPdes Security Advisory: HPSBST02386
http://marc.info/?l=bugtraq&m=122703006921213&w=2
HPdes Security Advisory: SSRT080164
http://marc.info/?l=bugtraq&m=122703006921213&w=2
Microsoft Security Bulletin: MS08-069
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-069
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5847
http://securitytracker.com/id?1021164
http://www.vupen.com/english/advisories/2008/3111




© 1998-2025 E-Soft Inc. All rights reserved.